{"id":6404,"date":"2017-01-27T04:30:53","date_gmt":"2017-01-27T12:30:53","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/01\/27\/news-241\/"},"modified":"2017-01-27T04:30:53","modified_gmt":"2017-01-27T12:30:53","slug":"news-241","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/01\/27\/news-241\/","title":{"rendered":"Right answer, wrong question"},"content":{"rendered":"<p>This credit union updates its online banking website, so a pilot fish with accounts there updates all her family&#8217;s accounts.<\/p>\n<p>&#8220;The new feature was security questions,&#8221; says fish. &#8220;I didn&#8217;t like the three that were given, so I did the drop-down to see more questions. I chose my three new questions and wrote down the answers so the spouse knew what they were.&#8221;<\/p>\n<p>But the first time he tries it, he blows the password. Fish has to go through the whole process of recreating the account setup.<\/p>\n<p>Next time he tries, fish has to go through the entire process <i>again<\/i> &#8212; but this time she prints out screen captures of the questions she chose, and writes the answers on them.<\/p>\n<p>To make sure it doesn&#8217;t happen a third time, fish walks him through the process of logging in. But when they get to the security question, the one that pops up is <i>not<\/i> one of the new questions fish has selected.<\/p>\n<p>&#8220;I purposely chose questions I knew he could answer,&#8221; fish says. &#8220;I bypassed the question about what high school I had graduated from, but there it was, waiting for an answer.<\/p>\n<p>&#8220;On my last try of the three-tries-or-you&#8217;re-locked-out scenario, I remembered that was the first question of their three original choices. So I supplied the answer I had used for the first question, &#8216;Where were you born?&#8217; Bingo, I was in.&#8221;<\/p>\n<p>This is ridiculous, fish thinks. She puts in a call to the same customer service rep who has already reset the account&#8217;s password twice. The rep tells fish that a whole lot of people are getting locked up on the security questions.<\/p>\n<p>Can I talk to the programmer? fish asks. I can&#8217;t transfer you, rep says.<\/p>\n<p>OK, write this down and give it to the IT department, fish says. Tell them that while they let users pick new questions, they&#8217;re recording the answers but keeping the original default questions as first presented.<\/p>\n<p>&#8220;I also asked where to send my bill for problem-solving consulting, but never heard back from them,&#8221; says fish.<\/p>\n<p>&#8220;But now we have a way of making the security questions unanswerable by hackers. For example, for the question &#8216;Where were you born?&#8217; we key in the year of the account holder&#8217;s birth as the answer.&#8221;<\/p>\n<p style=\"font-size: 0.875em;\"><strong>Answer Sharky&#8217;s call for true tales of IT life!<\/strong> <i>Send me your stories at <a href=\"mailto:sharky@computerworld.com\">sharky@computerworld.com<\/a>. You&#8217;ll snag a snazzy Shark shirt every time I use one. Comment on today&#8217;s tale at <a href=\"https:\/\/plus.google.com\/u\/0\/communities\/113252326043973101081\"><strong>Sharky&#8217;s Google+ community<\/strong><\/a>, and read thousands of great old tales in the <a href=\"http:\/\/www.computerworld.com\/search?query=+sharky&amp;s=d&amp;start=0\" title=\"Sharky's archives on easier-to-navigate pages\"><strong>Sharkives<\/strong><\/a>.<\/i><\/p>\n<p><em>Get your daily dose of out-takes from the IT Theater of the Absurd delivered directly to your Inbox. Subscribe now to the <a href=\"http:\/\/www.computerworld.com\/newsletters\/signup.html\" title=\"Daily Shark Newsletter subscription page\">Daily Shark Newsletter<\/a>.<\/em><\/p>\n<p><a href=\"http:\/\/www.computerworld.com\/article\/3162180\/security\/right-answer-wrong-question.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<article>\n<section class=\"page\">\n<p>This credit union updates its online banking website, so a pilot fish with accounts there updates all her family&#8217;s accounts.<\/p>\n<p>&#8220;The new feature was security questions,&#8221; says fish. &#8220;I didn&#8217;t like the three that were given, so I did the drop-down to see more questions. I chose my three new questions and wrote down the answers so the spouse knew what they were.&#8221;<\/p>\n<p>But the first time he tries it, he blows the password. Fish has to go through the whole process of recreating the account setup.<\/p>\n<p>Next time he tries, fish has to go through the entire process <i>again<\/i> &#8212; but this time she prints out screen captures of the questions she chose, and writes the answers on them.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3162180\/security\/right-answer-wrong-question.html#jump\">To read this article in full or to leave a comment, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714],"class_list":["post-6404","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6404"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6404\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6404"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}